Network Detection and Response
Finds the threat in the 95% of traffic that is encrypted — without decrypting it.
Ninety-five percent of network traffic is now encrypted, and most SOCs ignore two-thirds of their alerts to alert fatigue. Trellix Network Detection and Response (NDR) cuts through both problems: it detects threats inside encrypted traffic without decryption and uses a Risk Aggregation Framework to surface only the threats that pose genuine business risk. Faltrox runs the console and the investigations so the signal reaches a human.
Overview
What Network Detection and Response is
Trellix Network Detection and Response (NDR) transforms network security through intelligent risk prioritisation. Two problems break most network security today: 95% of traffic is now encrypted, creating blind spots deep packet inspection cannot see, and SOCs ignore the majority of their alerts to fatigue. NDR answers both — it detects threats inside encrypted traffic without decryption, and its Risk Aggregation Framework surfaces only the threats that pose genuine business risk.
It covers on-premises, cloud, and hybrid infrastructure through one platform, with native virtual sensors for AWS, Azure, and GCP and integrations reaching OT/ICS and IoT. Multilayered detection spans all 14 MITRE ATT&CK tactics, Active NDR contains threats in real time, and Trellix Wise GenAI turns junior analysts into effective threat hunters. Faltrox runs the console and the investigations so the signal reaches a human.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
On-Premises Networks
Unified visibility and detection across the corporate network from data centre to branch.
AWS, Azure & GCP
Purpose-built virtual sensors give native monitoring across multicloud environments.
OT/ICS & IoT
Integrations reach operational technology and IoT so those surfaces are not a blind spot.
Encrypted Traffic
JA3/JA3S fingerprinting and behavioural analysis find threats in encrypted flows without decryption.
Lateral Movement
Attack Path Discovery visualises how an attacker could escalate and move through the infrastructure.
Evasive Threats
Catches DNS tunnelling, ICMP exfiltration, newly registered domains, and SSL anomalies signatures miss.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
See
Sensors across physical, virtual, and cloud environments deliver unified visibility, including native monitoring of AWS, Azure, and GCP.
- 02
Detect
Behavioural analytics, machine learning, and threat intelligence detect across all 14 MITRE ATT&CK tactics, including inside encrypted traffic.
- 03
Prioritise
The Risk Aggregation Framework weighs asset criticality, vulnerability exposure, and ATT&CK tactics to surface only genuine business risk.
- 04
Investigate
Trellix Wise automatically analyses alerts, maps techniques, and recommends remediation, with full packet capture for forensic depth.
- 05
Contain
Active NDR blocks traffic, isolates systems, and coordinates with integrated tools to stop the attack in real time.
Capabilities
Key capabilities
Encrypted Traffic Analysis
JA3/JA3S fingerprinting, certificate reputation, and behavioural analysis reveal threats hiding in encrypted communications without decryption — keeping privacy compliance while closing the biggest modern blind spot.
Risk Aggregation Framework
Combines asset criticality, vulnerability data, and MITRE ATT&CK tactics to automatically prioritise threats, so analysts see genuine business risk rather than a flat stream of generic alerts.
Attack Path Discovery
Visualises potential attack vectors by combining vulnerability data with network topology, showing how an attacker could escalate and move laterally — so critical vulnerabilities get fixed before exploitation.
Multilayered Kill-Chain Detection
Behavioural analytics, machine learning, and threat intelligence detect across all 14 MITRE ATT&CK tactics, catching DNS tunnelling, ICMP exfiltration, newly registered domains, and SSL anomalies signatures miss.
Active NDR
Immediate containment through automated response — traffic blocking, system isolation, and coordinated action with integrated security tools to stop an attack in real time.
Hybrid & Multicloud Visibility
Purpose-built virtual sensors provide native monitoring for AWS, Azure, and GCP alongside on-premises, unifying visibility across IT, OT/ICS, IoT, and cloud on one platform.
Trellix Wise Investigation
GenAI automatically analyses alerts, maps techniques to ATT&CK, identifies affected entities, and recommends remediation — turning junior analysts into effective threat hunters.
Advanced Forensics
Complete packet capture and metadata retention with timeline reconstruction and attack visualisation, so an investigation understands full scope and prevents recurrence.
Specifications
Technical detail
- Sensor Throughput
- NDR Sensor (NX Evolution) up to 40 Gbps; IPS "NDR Ready" up to 240 Gbps
- Cloud Sensors
- Native virtual sensors for AWS, Azure, GCP
- Detection Coverage
- All 14 MITRE ATT&CK tactics
- Deployment
- Physical, virtual, and cloud
- Add-ons
- Full Packet Capture, IVX dynamic file analysis, Attack Path Discovery; integrations with SWG, firewalls, proxies, OT platforms
Works with
Part of the platform
Trellix products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Trellix Network Detection and Response for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01How does it detect threats in encrypted traffic without decrypting it?
Through JA3/JA3S fingerprinting, certificate reputation analysis, and behavioural analysis of the encrypted flow — the metadata and behaviour of the connection, not its contents. That keeps you compliant with privacy requirements while still seeing threats that deep packet inspection cannot.
02Our SOC already ignores most of its alerts. How is this different?
That is the problem the Risk Aggregation Framework targets. Instead of scoring every event equally, it weights asset criticality, vulnerability exposure, and ATT&CK tactics to surface only genuine business risk. The goal is fewer, higher-fidelity alerts a human actually acts on.
03Does it cover cloud and OT, or just the corporate network?
Both. Virtual sensors give native monitoring for AWS, Azure, and GCP, and it integrates with OT security platforms like Nozomi Guardian — so IT, OT/ICS, IoT, and cloud sit under one view rather than separate tools.
04Can it actually stop an attack, or only alert?
Active NDR performs automated response — blocking traffic, isolating systems, and coordinating with integrated tools — so containment happens in real time rather than waiting on manual action.
05How does this relate to Trellix Network Security and IPS?
The NDR Sensor evolves from the Network Security (NX) line, and IPS "NDR Ready" combines full intrusion prevention with NDR at up to 240 Gbps. Faltrox scopes which form factor fits your throughput and whether you need inline prevention alongside detection.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us